f7a262ac9a
Build & push images / images (push) Successful in 6m31s
apps/trainer (parking-trainer): inspect / train / evaluate / publish. Reads the wash collector's SQLite + crops read-only off its volume; time split (validation = newest slice); thin classes dropped; damped class weights; `features` mode (frozen ImageNet backbone, on-disk feature cache, seconds to retrain) and `finetune` mode (light augmentation). CPU-only torch from PyTorch's wheel index. ONNX export checked against the torch model; NO model file below the validation floor (exit 3, report still written); exit 2 = not enough labels. `evaluate` scores a shipped model on labels reviewed after training + the unlabelled pile; `publish` PUTs a version folder to a Gitea generic package. Light core deps; the `train` extra is heavy — CI syncs without it, torch tests skip. apps/vision: BodyTypeClassifier (bodytype.onnx + sidecar = the preprocessing contract: crop margin, input size, RGB 0-255, normalisation inside the graph) and RefinedVehicleDetector over YOLOX — refines only `car` or a class the classifier trained on, min-confidence, `detector_class` on the result; path set but no file = phase B off without an error; a broken file is a health detail. models/bodytype.version (tracked, empty) pins the published version the Dockerfile fetches at build (BuildKit secret; a pin that cannot be fetched fails the build). Verified: a trainer model gives identical probabilities inside the vision service; both images built and smoke-tested. Delivery: parking-trainer image in build-images.yml, the `trainer` compose profile on the collector stack (CPU, read-only data, TRAINER_OUT), commented TRAINER_OUT/PUBLISH_TOKEN in the wash-collector stack, .dockerignore for both Python contexts, trainer deps synced in CI. Wiki: bodytype-classifier-training rewritten as built (+ one fleet model not per site, secrets/access, where the crops live), opencv-anpr-service §Phase B, vision-review-outbox, vision-service-packaging, fleet-deployment-komodo, index, log. Claude-Session: https://claude.ai/code/session_01FWncR69HgGPuei1dLrW3cU
166 lines
6.8 KiB
YAML
166 lines
6.8 KiB
YAML
name: Build & push images
|
|
|
|
# Build the SERVER (API + SPA), COLLECTOR (wash review), VISION (ANPR) and TRAINER (phase-B job) container images and push them to the
|
|
# house Gitea registry, tagged by BRANCH + short SHA (branch-aware: dev→:dev, stage→:stage,
|
|
# main→:main). Separate from ci.yml (checks-only) and release.yml (tag-only desktop bundle).
|
|
# Mirrors the house pattern (cf. trm/processor build.yml). See
|
|
# wiki/decisions/container-deployment.md and fleet-deployment-komodo.md (dev→stage→main tiers).
|
|
|
|
on:
|
|
push:
|
|
branches: [dev, stage, main]
|
|
paths:
|
|
- 'apps/server/**'
|
|
- 'apps/web/**'
|
|
- 'apps/vision/**'
|
|
- 'apps/collector/**'
|
|
- 'apps/trainer/**'
|
|
- 'packages/**'
|
|
- 'package.json'
|
|
- 'pnpm-lock.yaml'
|
|
- 'pnpm-workspace.yaml'
|
|
- 'turbo.json'
|
|
- 'docker-compose*.yml'
|
|
- '.dockerignore'
|
|
- '.gitea/workflows/build-images.yml'
|
|
# Deploy/IaC changes (compose above, plus the Komodo Stack defs) also rebuild — so a
|
|
# promotion or a Stack tweak gets the same build+checks sanity pass before it reaches a
|
|
# booth, and a komodo-only push to `stage` still produces a :stage image.
|
|
- 'komodo/**'
|
|
workflow_dispatch:
|
|
|
|
env:
|
|
REGISTRY: git.infra.msai.al/mca/parking_solution
|
|
|
|
jobs:
|
|
images:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Set up Node 22
|
|
uses: actions/setup-node@v4
|
|
with:
|
|
node-version: 22
|
|
|
|
- name: Enable pnpm
|
|
run: corepack enable && corepack prepare pnpm@10.24.0 --activate
|
|
|
|
- name: Install dependencies
|
|
run: pnpm install --frozen-lockfile
|
|
|
|
- name: Set up uv (for @parking/vision checks)
|
|
# Install uv via its official standalone script rather than a third-party action —
|
|
# the Gitea runner can't reliably resolve astral-sh/setup-uv. uv provisions the
|
|
# pinned Python (apps/vision/.python-version) itself. Add it to PATH for later steps.
|
|
run: |
|
|
curl -LsSf https://astral.sh/uv/install.sh | sh
|
|
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
|
|
|
|
- name: Sync vision deps
|
|
working-directory: apps/vision
|
|
run: uv sync --frozen
|
|
|
|
- name: Sync trainer deps
|
|
# Light core only — NOT the `train` extra (CPU torch, ~200 MB); the torch tests skip.
|
|
working-directory: apps/trainer
|
|
run: uv sync --frozen
|
|
|
|
# Don't publish a broken image — run the same checks as ci.yml first.
|
|
- name: Build + lint + test (Turbo)
|
|
run: pnpm turbo run build lint test
|
|
|
|
- name: Compute tags
|
|
id: meta
|
|
# BRANCH = the pushed branch (dev|main); SHA = short commit. Two tags per image:
|
|
# the moving branch tag + an immutable branch-SHA tag.
|
|
run: |
|
|
BRANCH="${GITHUB_REF_NAME}"
|
|
SHA="$(echo "${GITHUB_SHA}" | cut -c1-7)"
|
|
echo "branch=${BRANCH}" >> "$GITHUB_OUTPUT"
|
|
echo "sha=${SHA}" >> "$GITHUB_OUTPUT"
|
|
|
|
- name: Set up Docker Buildx
|
|
uses: docker/setup-buildx-action@v3
|
|
with:
|
|
driver: docker-container
|
|
|
|
- name: Login to Gitea Registry
|
|
uses: docker/login-action@v3
|
|
with:
|
|
registry: git.infra.msai.al
|
|
username: ${{ secrets.REGISTRY_USERNAME }}
|
|
password: ${{ secrets.REGISTRY_PASSWORD }}
|
|
|
|
- name: Build & push SERVER (API + SPA)
|
|
uses: docker/build-push-action@v5
|
|
with:
|
|
context: .
|
|
file: apps/server/Dockerfile
|
|
push: true
|
|
build-args: |
|
|
BUILD_VERSION=${{ steps.meta.outputs.branch }}-${{ steps.meta.outputs.sha }}
|
|
tags: |
|
|
${{ env.REGISTRY }}/parking-server:${{ steps.meta.outputs.branch }}
|
|
${{ env.REGISTRY }}/parking-server:${{ steps.meta.outputs.branch }}-${{ steps.meta.outputs.sha }}
|
|
cache-from: type=registry,ref=${{ env.REGISTRY }}/parking-server:buildcache
|
|
cache-to: type=registry,ref=${{ env.REGISTRY }}/parking-server:buildcache,mode=max
|
|
|
|
- name: Build & push COLLECTOR (wash review)
|
|
uses: docker/build-push-action@v5
|
|
with:
|
|
context: .
|
|
file: apps/collector/Dockerfile
|
|
push: true
|
|
tags: |
|
|
${{ env.REGISTRY }}/parking-collector:${{ steps.meta.outputs.branch }}
|
|
${{ env.REGISTRY }}/parking-collector:${{ steps.meta.outputs.branch }}-${{ steps.meta.outputs.sha }}
|
|
cache-from: type=registry,ref=${{ env.REGISTRY }}/parking-collector:buildcache
|
|
cache-to: type=registry,ref=${{ env.REGISTRY }}/parking-collector:buildcache,mode=max
|
|
|
|
- name: Build & push VISION (ANPR)
|
|
uses: docker/build-push-action@v5
|
|
with:
|
|
context: apps/vision
|
|
file: apps/vision/Dockerfile
|
|
push: true
|
|
# The phase-B body-type classifier is fetched from the Gitea generic package registry
|
|
# at build when apps/vision/models/bodytype.version pins a version (empty = none). The
|
|
# registry user's credentials double as the fetch auth (BuildKit secret, never a layer).
|
|
secrets: |
|
|
bodytype_auth=${{ secrets.REGISTRY_USERNAME }}:${{ secrets.REGISTRY_PASSWORD }}
|
|
tags: |
|
|
${{ env.REGISTRY }}/parking-vision:${{ steps.meta.outputs.branch }}
|
|
${{ env.REGISTRY }}/parking-vision:${{ steps.meta.outputs.branch }}-${{ steps.meta.outputs.sha }}
|
|
cache-from: type=registry,ref=${{ env.REGISTRY }}/parking-vision:buildcache
|
|
cache-to: type=registry,ref=${{ env.REGISTRY }}/parking-vision:buildcache,mode=max
|
|
|
|
- name: Build & push TRAINER (phase-B job)
|
|
uses: docker/build-push-action@v5
|
|
with:
|
|
context: apps/trainer
|
|
file: apps/trainer/Dockerfile
|
|
push: true
|
|
tags: |
|
|
${{ env.REGISTRY }}/parking-trainer:${{ steps.meta.outputs.branch }}
|
|
${{ env.REGISTRY }}/parking-trainer:${{ steps.meta.outputs.branch }}-${{ steps.meta.outputs.sha }}
|
|
cache-from: type=registry,ref=${{ env.REGISTRY }}/parking-trainer:buildcache
|
|
cache-to: type=registry,ref=${{ env.REGISTRY }}/parking-trainer:buildcache,mode=max
|
|
|
|
# Optional: trigger a Komodo stack redeploy (cf. trm/processor). Enable by setting the
|
|
# KOMODO_* secrets; left guarded so it no-ops until the parking stack is wired.
|
|
- name: Trigger Komodo redeploy
|
|
if: success() && vars.KOMODO_ENABLED == 'true'
|
|
env:
|
|
URL: ${{ secrets.KOMODO_STACK_WEBHOOK_URL }}
|
|
SECRET: ${{ secrets.KOMODO_WEBHOOK_SECRET }}
|
|
run: |
|
|
body="{\"ref\":\"refs/heads/${GITHUB_REF_NAME}\"}"
|
|
sig=$(printf '%s' "$body" | openssl dgst -sha256 -hmac "$SECRET" | awk '{print $2}')
|
|
curl -fsS -X POST \
|
|
-H 'Content-Type: application/json' \
|
|
-H "X-Hub-Signature-256: sha256=$sig" \
|
|
-d "$body" \
|
|
"$URL"
|